<Vulnerability name="CVE-2026-66780">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Important</ThreatSeverity>
    <PublicDate>2026-08-18T16:35:00</PublicDate>
    <Bugzilla id="2507524" url="https://bugzilla.redhat.com/show_bug.cgi?id=2507524" xml:lang="en:us">
submariner-operator: Broker ServiceAccount Secret (token + CA) logged in full at TRACE verbosity
    </Bugzilla>
    <CVSS3 status="verified">
        <CVSS3BaseScore>6.5</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-532</CWE>
    <Details xml:lang="en:us" source="Mitre">
A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, which is assigned to joined clusters, possesses excessive permissions. This allows a compromised cluster to alter network configurations, specifically by overwriting other clusters' endpoint information. Consequently, an attacker can redirect inter-cluster tunnel traffic, enabling a Man-in-the-Middle (MITM) attack across the entire cluster mesh.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, which is assigned to joined clusters, possesses excessive permissions. This allows a compromised cluster to alter network configurations, specifically by overwriting other clusters' endpoint information. Consequently, an attacker can redirect inter-cluster tunnel traffic, enabling a Man-in-the-Middle (MITM) attack across the entire cluster mesh.
    </Details>
    <Statement xml:lang="en:us">
Critical: Red Hat Advanced Cluster Management for Kubernetes is vulnerable to a critical flaw in the submariner-operator where a compromised spoke cluster can achieve a Man-in-the-Middle (MITM) attack across the entire cluster mesh. This is due to the `submariner-k8s-broker-cluster Role` granting overly broad permissions, allowing any joined cluster to modify endpoint configurations for all other clusters within the broker namespace. This broad access enables an attacker to redirect inter-cluster tunnel traffic.
    </Statement>
    <Mitigation xml:lang="en:us">
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
    </Mitigation>
    <AffectedRelease cpe="cpe:/a:redhat:acm:2.17::el9">
        <ProductName>Red Hat Advanced Cluster Management for Kubernetes 2.17</ProductName>
        <ReleaseDate>2026-09-03T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:63016">RHSA-2026:63016</Advisory>
        <Package name="rhacm2/subctl-rhel9">rhacm2/subctl-rhel9:1788105072</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:acm:2.17::el9">
        <ProductName>Red Hat Advanced Cluster Management for Kubernetes 2.17</ProductName>
        <ReleaseDate>2026-09-03T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:63016">RHSA-2026:63016</Advisory>
        <Package name="rhacm2/submariner-rhel9-operator">rhacm2/submariner-rhel9-operator:1788073481</Package>
    </AffectedRelease>
    <PackageState cpe="cpe:/a:redhat:acm:2">
        <ProductName>Red Hat Advanced Cluster Management for Kubernetes 2</ProductName>
        <FixState>Affected</FixState>
        <PackageName>rhacm2/submariner-addon-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:acm:2">
        <ProductName>Red Hat Advanced Cluster Management for Kubernetes 2</ProductName>
        <FixState>Affected</FixState>
        <PackageName>rhacm2/submariner-operator-bundle</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-66780
https://nvd.nist.gov/vuln/detail/CVE-2026-66780
    </References>
</Vulnerability>